Insights

Cross-Border Mobile Money Compliance in East Africa: Name Verification and Data Protection

As cross-border mobile-money transfers expand across East Africa, payment providers must balance instant recipient verification with data protection, fraud prevention and anti-money-laundering obligations.

cross-border-mobile-money-compliance-east-africa

Caroline Mutalemwa, Partner – Banking and Finance Law Specialist


Cross-border mobile money is changing how individuals and businesses transfer funds across East Africa. Transactions that previously required several days can now be initiated and completed within minutes, supporting trade, remittances and wider financial inclusion.

However, the speed and convenience of these services create an important compliance challenge: how can a payment provider confirm that funds are being sent to the correct person without processing or transferring personal data unlawfully?

Why recipient name verification matters

Before completing a mobile-money transfer, the sending payment provider should be able to confirm that the registered name attached to the receiving wallet corresponds with the intended beneficiary.

Although this appears to be a simple step, it performs several important functions. Recipient verification can help:

  • prevent transfers to an incorrect mobile-money account;
  • identify inconsistencies that may indicate fraud or identity theft;
  • support sanctions and watchlist screening;
  • strengthen Know Your Customer compliance;
  • protect customers from avoidable financial loss; and
  • provide a reliable record where a transaction is later disputed.

Where payment systems operate across national borders, the verification process may require information to move between mobile-network operators, banks, payment switches and other service providers located in different jurisdictions.

This is where payment regulation and data protection law meet.

A regional payment system governed by national laws

East African countries are working towards greater regional payment integration. However, personal data continues to be regulated primarily at the national level.

A payment corridor involving Tanzania, Kenya and Uganda may therefore be subject to different requirements concerning the collection, disclosure, storage and cross-border transfer of customers’ personal information.

Names, telephone numbers, identification details and account information will generally constitute personal data. Payment providers must consequently establish a lawful basis for processing this information and apply appropriate technical and organisational safeguards.

Tanzania

Tanzania’s Personal Data Protection Act, 2022 and its implementing regulations regulate the collection, use, storage and transfer of personal data.

Payment providers operating in Tanzania should consider whether they are required to register as data controllers or data processors, maintain the required privacy and security controls, and obtain the necessary authorisation before transferring personal data outside Tanzania.

The Personal Data Protection Commission regulates and oversees cross-border transfers to ensure that personal data transferred outside the country receives an adequate level of protection.

Kenya

Kenya’s Data Protection Act, 2019 applies to organisations processing personal data relating to individuals located in Kenya, including financial-services and telecommunications providers.

Cross-border transfers should be supported by a recognised legal basis and adequate safeguards. Depending on the circumstances, these may include an adequacy assessment, contractual protections, consent or another lawful transfer mechanism.

Payment providers should also ensure that customers receive clear information about how their data will be used, who may receive it and whether it will be processed outside Kenya.

Uganda

Uganda’s Data Protection and Privacy Act, 2019 also establishes obligations governing the collection, processing, security and transfer of personal data.

Providers should assess the legal basis for any cross-border disclosure, the level of protection available in the receiving country and the safeguards imposed on participating operators and technology providers.

The compliance challenge for payment providers

A cross-border transaction may involve a sending operator, a receiving operator, an intermediary bank, a regional payment switch, cloud infrastructure and third-party identity-verification services.

Each participant may process part of the customer’s information. Without a clearly documented compliance structure, it may be difficult to determine:

  • which entity acts as the data controller or data processor;
  • what information may lawfully be exchanged;
  • where the information will be stored;
  • how long transaction and verification records should be retained;
  • who is responsible for responding to a data breach;
  • how customers may exercise their data-protection rights; and
  • which country’s regulator has jurisdiction.

These questions should be resolved before a new payment corridor or digital product goes live.

Four practical compliance measures

1. Establish clear data-sharing agreements

Participating operators should put written agreements in place governing the collection, use, disclosure, security, retention and deletion of recipient-verification information.

The agreements should define the responsibilities of each party and establish safeguards appropriate to every country through which the information passes.

2. Return verification results instead of complete records

Where possible, the receiving operator should provide a confirmation or match result rather than disclose the customer’s entire identification record.

Applying data minimisation in this way reduces unnecessary exposure while still allowing the sending operator to verify the intended beneficiary.

3. Introduce automated discrepancy controls

A material difference between a wallet name, account name or verified identity should trigger an automated review before settlement.

The system should record why a transaction was stopped, approved or escalated. This creates an audit trail and reduces reliance on informal manual decisions.

4. Assess localisation and infrastructure requirements

Providers should identify where customer information is processed and stored, including information handled by cloud-service providers and regional switches.

Where national rules restrict or regulate cross-border transfers, in-country processing nodes, encrypted application programming interfaces and decentralised storage may reduce legal and operational risk.

Compliance should begin at the design stage

Cross-border payment compliance should not be treated as an issue to resolve after a product has been launched.

Banks, fintech companies, mobile-network operators and payment service providers should conduct legal and data-protection assessments during product development. This allows the system architecture, contractual arrangements and customer communications to be designed around applicable regulatory requirements.

A properly structured recipient-verification process can support faster payments without compromising privacy, consumer protection or financial-crime controls.

How Leyrand Law Firm can assist

Leyrand Law Firm advises banks, fintech companies, mobile-network operators, payment service providers and technology companies on the legal and regulatory requirements affecting digital financial services in Tanzania and across East Africa.

Our support includes:

  • payment-product and payment-corridor legal assessments;
  • fintech and financial-services regulatory advice;
  • data-protection compliance reviews;
  • cross-border data-transfer assessments;
  • data-sharing and processing agreements;
  • privacy notices and customer consent frameworks;
  • Know Your Customer and anti-money-laundering compliance;
  • data-protection impact assessments;
  • regulatory applications and engagement; and
  • legal review of payment-system and technology architecture.

To discuss the legal requirements affecting your cross-border payment operations, contact:

Caroline Mutalemwa
Partner – Banking and Finance Law Specialist
carolinemutalemwa@leyrand.org

This publication provides general legal information and does not constitute legal advice. Specific advice should be obtained in relation to the relevant payment corridor, transaction structure and jurisdiction.